Server data from the Official MCP Registry
Cloudflare Worker for read-only recall of cambium knowledge. MCP 2026-07-28, dual-era.
About
Cloudflare Worker for read-only recall of cambium knowledge. MCP 2026-07-28, dual-era.
Remote endpoints: streamable-http: https://cambium-remote.{account}.workers.dev/mcp/{token}
Security Report
A well-architected read-only MCP server with strong authentication, proper credential handling, and well-scoped permissions. The code demonstrates security-conscious design with constant-time token comparison, comprehensive input validation, and protocol negotiation safeguards. Minor code quality findings around error handling and logging practices do not materially affect security posture. Supply chain analysis found 2 known vulnerabilities in dependencies (1 critical, 1 high severity).
6 files analyzed · 7 issues found
Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.
Permissions Required
This plugin requests these system permissions. Most are normal for its category.
How to Install & Connect
Available as Local & Remote
This plugin can run on your machine or connect to a hosted endpoint. during install.
Documentation
View on GitHubFrom the project's GitHub README.
cambium-remote
Part of the xylem stack.
A Cloudflare Worker MCP server that makes cambium's promoted knowledge recallable from claude.ai (including mobile) — read-only.
Local cambium is a desktop stdio server; its team knowledge lives on a
cambium branch of each project repo and its org knowledge lives in a
dedicated knowledge repo — both plain knowledge.json files in git. This Worker
reads those files through the GitHub Contents API and serves recall() over
them, the same pattern agentsync-remote
uses for the coordination board.
Read-only by design. It exposes recall and status. It does not
distill, endorse, or promote (those are CAS writes / the generalization
gate — desktop-only), and recall here does not increment recall counts (so
it never feeds promotion). Local (personal, unpromoted) scope is desktop-only
and not reachable remotely — only the promoted team and org tiers are.
Tools
recall(query, scope?, limit?)— search team + org knowledge.scope:auto(default, team+org) |team|org. Abstains withno_confident_matchbelow the relevance floor, exactly like local cambium.status()— what the Worker is configured to read and how many active items each scope holds. Call it first if recall looks empty.
Configure (wrangler.toml vars)
Team scope auto-discovers — it is a growing set, not a static list. Every
repo owned by TEAM_OWNER that has a TEAM_BRANCH (i.e. has been
team-promoted) is read, so a newly-promoted repo shows up on mobile within
minutes with no redeploy. One GraphQL scan per few minutes (cached in-isolate)
lists the repos; a repo without the branch is simply skipped.
| var | meaning |
|---|---|
ORG_REPO | owner/name of the dedicated org knowledge repo (its default branch's knowledge.json). Blank = no org recall. |
TEAM_OWNER | owner (user/org) to auto-discover team repos under. Every repo of theirs with TEAM_BRANCH is read. Blank = no team recall. |
TEAM_REPOS | optional extra owner/name repos to include on top of discovery (e.g. under a different owner). Blank in the common case. |
TEAM_BRANCH | team-scope branch (default cambium). |
KNOWLEDGE_PATH | file name (default knowledge.json). |
Deploy
npm install
npm run typecheck && npm test
npx wrangler deploy
# then set the two secrets in the Cloudflare dashboard (never in the repo):
npx wrangler secret put AUTH_TOKEN # the path-token credential; URL is /mcp/<AUTH_TOKEN>
npx wrangler secret put GH_PAT # fine-grained GitHub token: Metadata: Read + Contents: Read across your repos
# # (team scope is auto-discovered, so it needs to see all of TEAM_OWNER's repos)
Then add https://cambium-remote.<subdomain>.workers.dev/mcp/<AUTH_TOKEN> as a
custom connector in claude.ai → Settings → Connectors. The whole URL is the
credential — treat it like a password.
Auth
Path-token: POST /mcp/<token>, constant-time compared to the AUTH_TOKEN
secret; anything else returns a bare 404. Same scheme as the sibling Workers.
License
PolyForm Noncommercial License 1.0.0 — free for any noncommercial use.
Reviews
No reviews yet
Be the first to review this server!
More Developer Tools MCP Servers
Git
Freeby Modelcontextprotocol · Developer Tools
Read, search, and manipulate Git repositories programmatically
Toleno
Freeby Toleno · Developer Tools
Toleno Network MCP Server — Manage your Toleno mining account with Claude AI using natural language.
mcp-creator-python
Freeby mcp-marketplace · Developer Tools
Create, build, and publish Python MCP servers to PyPI — conversationally.
MarkItDown
Freeby Microsoft · Content & Media
Convert files (PDF, Word, Excel, images, audio) to Markdown for LLM consumption
MCP Marketplace
Freeby mcp-marketplace · Developer Tools
Search and install MCP servers from inside your AI client.
FinAgent
Freeby mcp-marketplace · Finance
Free stock data and market news for any MCP-compatible AI assistant.
